Skip to main content
Promotional banner for the pentest readiness checklist
Category: Third-Party & Vendor

Vendor Due Diligence

Also known as: VDD, Supplier Due Diligence, Third-Party Due Diligence
Simply put

Vendor due diligence is the process of gathering and reviewing information about a supplier or other third party before entering into or continuing a business relationship with them. The goal is to understand who you are dealing with and to identify possible risks in areas such as finances, legal standing, and operations. It is a practical risk-checking activity rather than a legally defined term, though it may support broader compliance obligations.

Formal definition

Vendor due diligence (VDD) is a structured evaluation process in which an organization collects and assesses financial, legal, operational, and related information about a vendor, supplier, or comparable third party to determine the risks of establishing or maintaining a relationship. In a third-party risk management context, it generally functions as a pre-engagement and ongoing-monitoring control to verify vendor legitimacy and surface apparent risks. Note that the term carries a distinct meaning in mergers and acquisitions, where VDD refers to an in-depth analysis of a target's financial, legal, and operational aspects prepared on behalf of a seller to identify risks ahead of a transaction; practitioners should confirm which usage applies in a given setting. VDD is a business and risk practice rather than a binding legal requirement in itself, although it may be undertaken to help satisfy applicable regulatory or contractual obligations, which vary by jurisdiction and sector.

Why it matters

Organizations increasingly depend on third parties for critical functions, and a vendor's weaknesses can become the organization's own. Vendor due diligence matters because risks in a supplier's finances, legal standing, or operations can propagate into the engaging organization, potentially disrupting operations, exposing sensitive data, or creating regulatory or contractual exposure. Reviewing this information before and during a relationship allows an organization to make an informed decision about whether and how to engage a given vendor.

VDD generally functions as both a pre-engagement control, used to verify that a prospective vendor is legitimate and to surface apparent risks, and an ongoing-monitoring control applied over the life of the relationship. This dual role reflects that vendor risk is not static: a supplier's circumstances can change after onboarding, so a one-time check at the outset may not remain adequate. In most cases, VDD is undertaken as a business and risk-management practice rather than because a single statute mandates it by name.

Readers should note that VDD is not itself a binding legal requirement. It may, however, be undertaken to help satisfy applicable regulatory or contractual obligations, and those obligations vary considerably by jurisdiction and sector. Whether and to what depth due diligence is expected in a specific situation depends on the applicable law, the nature of the relationship, and the risks involved, and requires professional judgment rather than reliance on a general definition. The specific obligations that VDD might support are outside the scope of this entry and should be verified against current authoritative sources.

Who it's relevant to

Third-party risk and procurement teams
Those responsible for onboarding and managing suppliers use vendor due diligence as a pre-engagement and ongoing-monitoring control to verify vendor legitimacy and surface financial, legal, and operational risks before and during a relationship.
Compliance officers and legal counsel
Because VDD may be undertaken to help satisfy applicable regulatory or contractual obligations, compliance and legal professionals are often involved in defining its scope. Whether it is required, and to what depth, depends on jurisdiction, sector, and the specific facts, so professional judgment is needed rather than reliance on a general definition.
M&A advisors and deal teams
In a transactional context, VDD refers to a seller-side, in-depth analysis of a target's financial, legal, and operational aspects prepared to identify risks ahead of a transaction. Advisors should confirm this usage is intended, as it differs materially from the third-party risk management sense of the term.
Auditors and assessors
Professionals reviewing an organization's third-party risk management practices may examine whether and how vendor due diligence is performed, recognizing that it is a business and risk practice rather than a binding legal requirement in itself.

Inside VDD

Risk-Based Scoping
The process of tiering vendors according to the sensitivity of data they access, the criticality of the service they provide, and their level of system integration. Higher-risk vendors generally warrant deeper scrutiny, while lower-risk engagements may follow a lighter-touch review. Scope should be calibrated to the specific engagement rather than applied uniformly.
Security and Privacy Posture Review
An examination of the vendor's technical and organizational controls, which may include reviewing certifications or attestations such as ISO/IEC 27001 or SOC 2 reports. These are voluntary or contractual assurances rather than legal requirements, and their presence evidences a control environment but does not by itself guarantee compliance with any particular regulation.
Contractual and Data Protection Terms
Review of the agreements governing the relationship, including provisions that allocate responsibilities between the parties. Where a vendor processes personal data on behalf of the organization, the controller–processor distinction is relevant and data protection terms (such as those generally required under the GDPR for processor arrangements) may need to be addressed. The specific obligations depend on the applicable jurisdiction and the roles of each party.
Regulatory and Jurisdictional Assessment
Identification of which legal regimes apply to the engagement based on where data is processed, stored, and transferred, and the sectors involved. Requirements differ across the EU, the United States, the United Kingdom, and other jurisdictions, and cross-border data transfers may trigger additional obligations. This determination is fact-specific.
Ongoing Monitoring and Reassessment
Due diligence is not a one-time gate but a continuing activity. Vendor risk profiles, certification statuses, and applicable regulations change over time, so periodic reassessment and monitoring of the relationship are generally expected across the vendor lifecycle.
Documentation and Evidence Retention
Maintaining records of the review performed, findings, and decisions taken. Such documentation supports accountability and may assist in demonstrating that a reasonable, risk-appropriate process was followed, though retention expectations vary by jurisdiction and internal policy.

Common questions

Answers to the questions practitioners most commonly ask about VDD.

Does completing vendor due diligence make my organization compliant with data protection law?
No. Vendor due diligence is one component of a broader compliance program, not a substitute for it. Under regimes such as the GDPR, a controller generally remains accountable for the processing it entrusts to a processor, and due diligence alone does not discharge obligations like maintaining a lawful basis, executing a data processing agreement, or meeting security requirements. Due diligence helps assess whether a vendor can meet applicable requirements; it does not certify that either party is compliant. Application to specific arrangements requires professional judgment against the current official text of the relevant regime.
If a vendor holds an ISO/IEC 27001 certification or a SOC 2 report, does that mean no further due diligence is needed?
Not necessarily. Certifications and attestation reports are voluntary or contractual instruments that provide useful evidence, but they are not equivalent to regulatory compliance and do not automatically satisfy a customer's due diligence obligations. A SOC 2 report reflects an assessment against defined criteria over a stated scope and period, and an ISO/IEC 27001 certificate covers a defined scope of an information security management system. Neither guarantees that the specific services, data categories, or jurisdictional requirements relevant to your engagement are addressed. Reviewers should confirm scope, currency, version, and applicability rather than treating a certificate as a blanket assurance.
How do I decide how much due diligence a particular vendor warrants?
A risk-based approach is generally used, meaning the depth of review is calibrated to factors such as the category and volume of data involved, the criticality of the service, the level of system access granted, and the jurisdictions engaged. A vendor processing sensitive personal data or supporting critical operations typically warrants more extensive review than one with no access to regulated data. Organizations often tier vendors accordingly. The specific criteria and thresholds should reflect your own risk framework and any obligations applicable to your sector and jurisdiction.
What kinds of evidence are commonly requested during vendor due diligence?
Commonly requested items may include security policies, certifications or attestation reports (with attention to their scope and currency), audit or assessment results, evidence of technical and organizational measures, data flow and sub-processor information, incident response and breach notification arrangements, and contractual terms such as data processing agreements where personal data is involved. The relevant set depends on the risk tier, the applicable requirements, and the nature of the service. Evidence should be evaluated for scope and validity rather than accepted at face value.
How should sub-processors and onward transfers be handled in due diligence?
Where a vendor engages sub-processors, due diligence generally extends to understanding who those parties are, what they access, and how their engagement is governed, because obligations and accountability can flow through the supply chain. Where personal data may move across jurisdictions, reviewers typically examine the mechanisms relied upon for such transfers, as requirements differ across the EU, the United Kingdom, the United States, and other regions and continue to evolve. The specific mechanisms and their adequacy should be verified against the current authoritative sources for each jurisdiction involved.
Is vendor due diligence a one-time exercise performed before onboarding?
Generally not. While an initial review is typically conducted before engagement, due diligence is often treated as an ongoing activity, with periodic reassessment reflecting the vendor's risk tier, changes in the service or data involved, and changes in applicable requirements. Certifications and attestation reports have limited validity periods and versions change, so evidence collected at onboarding can become outdated. The appropriate cadence and triggers for re-review depend on your risk framework and the nature of the relationship.

Common misconceptions

A vendor holding a certification such as ISO/IEC 27001 or a SOC 2 report is automatically compliant with applicable regulations.
Certifications and attestations are voluntary or contractual assurances of a control environment, not legal compliance. They do not substitute for regulatory obligations, and their scope, version, and validity period should be verified. A certificate covering one set of systems or controls does not necessarily cover the specific service being procured.
Vendor due diligence is a one-time task completed before signing a contract.
Due diligence is generally an ongoing process. Vendor risk profiles, certification statuses, and applicable legal requirements change over time, so periodic monitoring and reassessment throughout the relationship are typically warranted.
Engaging a vendor as a processor transfers the organization's compliance responsibilities to that vendor.
The controller–processor distinction allocates responsibilities but does not eliminate the engaging organization's own obligations. In most cases the controller retains accountability for the processing, and contractual terms define, rather than fully offload, each party's duties.

Best practices

Tier vendors by risk based on data sensitivity, service criticality, and system integration, and calibrate the depth of review to each engagement rather than applying a uniform process.
Verify certifications and attestations against their current, authoritative source, confirming the scope, version, and validity period actually cover the service being procured.
Determine the applicable jurisdictions and roles (for example controller versus processor) early, and ensure contractual and data protection terms reflect the resulting obligations.
Assess cross-border data transfer arrangements where data is processed or stored outside the organization's jurisdiction, and confirm any additional requirements that may apply.
Establish ongoing monitoring and scheduled reassessment so that changes in vendor posture, certification status, or applicable regulation are captured throughout the relationship.
Document the review process, findings, and decisions to support accountability, and treat conclusions as informational rather than a substitute for professional judgment on specific facts.
Promotional banner for the Penetration Report Template Kit